Description
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the 'recent_decrypted_file' option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin's upload directory; without this prior admin action, there is no file to serve.
Published: 2026-07-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Backup and Staging by WP Time Capsule plug‑in for WordPress stores an admin‑decrypted SQL backup in its upload directory after a decryption operation. An authenticated user with subscriber‑level access or higher can call the download_recent_decrypted_file_wptc function to retrieve this file, which usually contains password hashes, user credentials, and other sensitive site configuration data. The flaw is an authorization bypass (CWE‑862) that allows the privileged user to download the backup even though normal file‑access controls should have restricted this action.

Affected Systems

WordPress sites using the Backup and Staging by WP Time Capsule plug‑in from revmakx. Versions up to and including 1.22.26.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while an EPSS score of < 1% suggests a low probability of exploitation at this time. The plug‑in is not listed in the CISA KEV catalog. Attackers must possess subscriber‑level or higher credentials and operate on a site where an administrator has previously performed a decrypt action, causing the decrypted backup file to exist in the plug‑in’s upload directory. Successful exploitation would expose sensitive database information to the attacker.

Generated by OpenCVE AI on July 28, 2026 at 08:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Backup and Staging by WP Time Capsule version 1.22.27 or later.
  • Remove any existing decrypted SQL backup files from the plug‑in’s upload directory to eliminate the data target.
  • Configure file permissions and access controls so that only administrators can trigger decryption or view the upload directory, mitigating the authorization flaw.

Generated by OpenCVE AI on July 28, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Revmakx
Revmakx backup And Staging By Wp Time Capsule
Wordpress
Wordpress wordpress
Vendors & Products Revmakx
Revmakx backup And Staging By Wp Time Capsule
Wordpress
Wordpress wordpress

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the 'recent_decrypted_file' option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin's upload directory; without this prior admin action, there is no file to serve.
Title Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Revmakx Backup And Staging By Wp Time Capsule
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-09T17:29:08.760Z

Reserved: 2026-05-19T13:31:06.616Z

Link: CVE-2026-8996

cve-icon Vulnrichment

Updated: 2026-07-09T17:29:05.503Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses